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Abstract 

We show that the value of a general two-prover quantum game cannot be computed by a semi- 
definite program of polynomial size (unless P=NP), a method that has been successful in more re- 
stricted quantum games. More precisely, we show that proof of membership in the NP-complete prob- 
lem GAP-3D-MATCHING can be obtained by a 2-prover, 1-round quantum interactive proof system 
where the provers share entanglement, with perfect completeness and soundness s = 1 — 2 — °W, 
and such that the space of the verifier and the size of the messages are O(logn). This implies that 
QMIP* log n J 1 _ 2 -o(") ^ P unless P = NP and provides the first non-trivial lower bound on the power 
of entangled quantum provers, albeit with an exponentially small gap. The gap achievable by our proof 
system might in fact be larger, provided a certain conjecture on almost commuting versus nearly com- 
muting projector matrices is true. 



1 Introduction 

Multi-prover interactive proof systems have played a tremendous role in classical computer science, in par- 
ticular in connection with probabilistically checkable proofs (PCPs). The discovery of the considerable 
expressive power of two-prover interactive proof systems, as expressed by the relation MIP = NEXP 
[BFL91], prompted a systematic study of the precise amount of resources (the randomness used by the 
verifier, and the amount of communication between him and the provers) necessary to maintain this ex- 
pressivity. These investigations culminated in a new characterization of NP, NP = PCP(0(log n), 0(1)) 
||ALM + 92l IAS9 21, known as the PCP Theorem. This characterization has had wide-ranging applications, 
most notably in the field of hardness of approximation, where it is the basis of almost all known results. 

The study of quantum interactive proofs was initiated by Watrous, who was the first to systematically 
study proof systems with one prover, whose power is only limited by the laws of quantum mechanics and 
who communicates quantum messages with a polynomially bounded quantum verifier (the class QIP). Ki- 
taev and Watrous showed [KWOO] that QIP (3), the class of quantum interactive proofs with 3 rounds can 
simulate all of QIP and is contained in the class EXP, i.e. IP C QIP = QIP (3) C EXP. The proof of 
the last inclusion uses the fact that the maximization task of the prover can be written as a semi-definite 
program (SDP) of exponential size together with the fact that there are efficient algorithms to compute their 
optimum IV B961IGLS88II . Moreover, Raz [Raz05 ] showed that the PCP theorem combined with quantum 
information can have surprising results in complexity theory. It would be interesting to formulate a purely 
quantum PCP theorem, which could arise from the in-depth study of quantum multi-prover interactive proof 
systems. 

'Supported in part by ACI Securite Informatique SI/03 511 and ANR AlgoQP grants of the French Research Ministry, and 
also partially supported by the European Commission under the Integrated Project Qubit Applications (QAP) funded by the 1ST 
directorate as Contract Number 015848. 

^Work done while at LRI, Univ. de Paris-Sud, Orsay. 
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When considering interactive proof systems with multiple provers, the laws of quantum mechanics en- 
able us to introduce an interesting new twist, namely, we can allow the provers to share an arbitrary (a 
priori) entangled state, on which they may perform any local measurements they like to help them an- 
swer the verifier's questions. This leads to the definition of the classes MIP* (communication is classical 
and provers share entanglement), QMIP (communication is quantum, but provers do not share entangle- 
ment) and QMIP* (communication is quantum and provers share entanglement). Kobayashi and Matsumoto 
[KM03] showed that QMIP = MIP, but the question of how entanglement influences the power of such 
proof systems remains wide openQ The fact that entanglement can cause non-classical correlations is a 
familiar idea in quantum physics, introduced in a seminal 1964 paper by Bell [Bel64]. It is thus a natural 
question to ask what the expressive power of entangled provers is. 

The only recent result in this direction is by Cleve et al. [CHTW04], who show, surprisingly, that 
©MIP* (2,1) C EXP, where ©MIP* (2,1) is the class of one-round classical interactive proofs where 
the two provers are allowed to share some arbitrary entangled state, but reply only a bit each, and the 
verifier bases his decision solely on the XOR of the two answer bitso This should be contrasted with the 
corresponding classical class without entanglement: it is known that ©MIP(2, 1) = NEXP due to work by 
Hastad [HasOl ]. The inclusion ©MIP* (2, 1) C EXP follows from the fact that the maximization problem 
of the two provers can be written as an SDP More precisely, there is an SDP relaxation with the property 
that its solutions can be translated back into a protocol of the provers. This is possible using an inner-product 
preserving embedding of vectors into two-outcome observables due to Tsirelson [Tsi80|. 

It is a wide open question whether it is true that MIP* C EXP or even QMIP* C EXP. Is it possible 
to generalize Tsirelson's embedding to study proof systems where the answers are not just one bit? The 
semi-definite programming approach has proved successful in the only known characterizations of quantum 
interactive proof systems: both for QIP and for ©MIP* (2, 1) it was shown that the success probability is 
the solution of a semi-definite program. Does this remain true when the provers reply more than one bit, 
or when messages are quantum? There are SDP relaxations for the success probability both in the case 
of MIP* and QMIP* ; is it possible that they are tight, implying inclusion in EXP? Or could it be on the 
contrary that NEXP C QMIP*? 

In this paper we provide a step towards answering these questions. We rule out the possibility that 
the success probability of QMIP* systems can be given as the solution of a semi-definite program (unless 
P = NP). Mainly for convenience, we state our results in the scaled down realm of polynomial time and 
logarithmic communication. Here the analogous question is whether NP C QMIP* logn , where the subscript 
log n indicates the corresponding proof system with communication and verifier's space logarithmic in the 
input size n. Our main result is the following: 

Theorem 1. NP C QMIP*i ognls (2, 1) with soundness s = 1 — C~ n for some constant C > 1. The 
verifier, when given oracle access to the input, requires only space and time O(logn). 

To our knowledge this is the first lower bound on the power of entangled provers. Note that even an 
exponentially small gap between completeness and soundness is not at all a triviality in our setting. For 
instance, it is not possible for the verifier to guess one of the exponentially many solutions, since he only has 
a logarithmic amount of space and randomness. We believe that our result is significant for the following 
reasons. First, we introduce novel techniques that exploit quantum messages and quantum tests directly. 
Our approach is to give a 2-prover, 1-round protocol for an NP-complete problem, GAP-3D-MATCHING 
(GAP-3DM), where the verifier sends quantum messages of length log n to each of the provers, who reply 
with messages of the same length. This protocol truly exploits the fact that the messages are quantum, and 
does not seem to work for classical messages. To give a vague intuition as to why quantum messages help, 

'it is still true that QMIP* C MIP when the provers share only a polynomial amount of entanglement. 
2 This result was recently strengthened by Wehner [Weh06|, who showed that ©MIP* (2, 1) C QIP(2). 
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imagine that the verifier wants to send a question u from a set U to the provers and to enforce that their 
answers v are given according to a bijection v = ir(u). He could exploit quantum messages by preparing 
the state \<p) = Ylu&u \ u )a\ u ) b an d sending one register to each of the provers. If the provers are honest, 
the resulting state is Ylu&u l 7r ( M )) a\^{u)) b', but of course, since the original state is invariant under a 
bijection, this is equal to the state \<f>). Hence, even not knowing it the verifier can measure the received 
state in a basis containing \<p) to get an indication whether the provers are honest. We use variations of 
this idea, together with the SWAP test, to derive conditions on the provers' behavior, forcing them to apply 
approximate bijections. 

Second, we pinpoint the bottleneck for decreasing soundness, which is related to the question: 

Given n pairwise almost commuting projectors, how well can we approximate them by n com- 
muting projectors? 

More precisely we link the soundness to the scaling of 5 in the following conjecture: 

Conjecture 2. Let Pi, ... , P m be projectors and D some diagonal matrix such that = 1 (where \\-\\f 

is the Frobenius norm) and ||(PjPj — PjP^D^p < e for all i,j £ {1, . . . , to}. Then there exist a 5 > 0, 
diagonal projectors Qi, . . . , Q m , and a unitary matrix U, such that Vi \\(Pi — UQiU^)D\\ 2 F < 8. 

Along with Theorem Q] we show the following 

Corollary 3. There are constants C, C, C" > such that if Conjecture \2\is true for m = Cn and 5 = 
5(n, e) then NP C QMIP* logn l l _ £ , for e' such that 5(n, C"e') < C. 

In particular if 5 = poly(n) ■ e we get soundness s = 1 — poZy(n) -1 and if S = 5(e) is constant 
(independent of n) we get constant soundness s, and in a scaled up version NEXP C QMIP*! s for constant 
sj| We show in Lemmal20lthat Conjecture |2]is true for S = 2°^ -e, which gives soundness s = 1 — 2~°( n \ 
We conjecture that Conjecture |2]is true for 5 = ne. 

Finally, our result has an important consequence: it shows that standard SDP techniques will not work 
to prove that QMIP* C EXP and that the success probability of quantum games cannot be computed by 
an SDP that is polynomial in the size of the verifier and of the messages (unless P=NP). In the case of 
QMIP* i og n with a logn-space verifier the SDP would have size polynomial in n@ It is well known that 
there are polynomial time algorithms to find the optimum of such SDP's up to exponential precision; in 
particular these algorithms could distinguish between success probability 1 and 1 — 2~°( n ) and hence they 
could solve NP- complete problems. 

Corollary 4. Quantum games with entangled quantum provers cannot be computed by an SDP that is 
polynomial in the dimension of the messages and of the verifier. 

Another related consequence of our result is that there is no generic way to prove QMIP* C QIP, be- 
cause our results imply QMIP* logn 11 _ 2 - (n) ^ QIPio g n,i i_2-°(™)> w h ere QiPiogni st h ec l ass °f' quantum 
interactive proofs with communication and verifier's size of order log n. This is true for the same reason as 
before: there is a polynomial size SDP for the success probability of QIPi ogn protocols. 

Related work: Ben Toner MTonl communicated to us existing attempts to show NP C MlPf n , which 
focus on showing that in the case that there are a large number of provers, imposing classical correlations 
on their answers can help restrain the nonlocal correlations that they exhibit to the point where they cannot 
cheat more than two classical unentangled provers. It is possible by symmetrization to obtain a relation 

3 Note that proving Conjecture[2]for D proportional to the identity matrix would give the corresponding result for provers that 
share a maximally entangled state. 

Note that the SDP depends on the instance x of GAP-3DM, but can be constructed from x in polynomial time. 
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which has some resemblance to Conjecture [2] (although in the operator norm, where the conjecture is false), 
where e is inverse proportional to the number of provers in the protocol. After the completion of this 
work, we have heard of related work showing that NP C MIP* n c s (3, 1), independently by Ben Toner, 
and Hirotada Kobayashi and Keiji Matsumoto. We can therefore also conclude that semidefinite programs 
cannot compute the value of games with three entangled provers and classical communication. Furthermore 
we have just learned from Hirotada Kobayashi and Keiji Matsumoto about another lower bound on two- 
pro ver quantum systems that shows IP = PS PACE C QMIP* with inverse polynomial soundness; and the 
authors communicated to us that they were currently working on possibly extending this to a statement on 
NEXP with simply exponential gap. 

The structure of this paper is as follows: In Section|2]we introduce the necessary definitions and notations 
and give the version of GAP-3DM we use. In Section[3]we show that GAP-3DM can be put into a zero-error 
version of QMIP* logn (2, 1). We then show in Section [4] that the zero-error requirement can be relaxed to 
soundness 1 — 2~°(™) proving Theorem Q] and Corollary [3] In Section [5] we elaborate on Conjecture [2] and 
briefly discuss scaling-up to proving NEXP C QMIP* X s (2, 1). 

2 Preliminaries 

We assume basic knowledge of quantum computation [NCOO] and of classical interactive proof systems 
!ILun921 . The relevant classes of quantum interactive proof systems are defined as follows. 

Definition 5. A (n, r, m) classical (resp. quantum) interactive proof system is given by a polynomial-time 
classical (resp. quantum) circuit (the verifier V) that runs in space 0(m). V interacts with n infinitely 
powerful quantum provers through n special classical (resp. quantum) channels. The verifier is allowed 
to communicate at most 0(m) bits (resp. qubits) in a maximum of r rounds of interaction through his 
communication channels. 

Let MIP*^ c s (n,r) (resp. QMIP* m c s (n, r)) denote the class of languages L such that there exists a 
(n, r, m) classical (resp. quantum) interactive proof system such that 

• Vx € L, there exist n provers who share a n-partite state \^) such that the interaction between V and 
the provers results in the verifier accepting with probability at least c over his random choices. 

• Vx ^ L and for all n provers who share any n-partite state \^) the interaction between V and the 
provers results in the verifier accepting with probability at most s over his random choices. 

Most of the time we consider only 2-prover 1-round protocols and omit the (2, 1). 

To show our main result we will work with the following gapped instance of 3D-MATCHING: 

Definition 6. An instance o/e-GAP-3DM of size n is given by three sets U, V, W with \U\ = \ V\ = \W\ = 
n, and a subset M C U x V x W. For a positive instance there exist two bijections ir : U — » V and 
a : U — > W such that 

Vu£U (u,ir(u),o-(u)) E M 

For a negative instance, for all bijections ir : U — » V and a : U — » W, at most a fraction e of triples 
(u, 7r(u), cr(u)), for u S U, are in M. 

Fact 7. There exists constants A G N and e > such that the restriction of e-GAP-3DM to instances 
where M has outgoing degree bounded by A (for each u £ U there are neighborhoods Ny (u) C V and 
Nyy (u) C W such that \ Ny (u) I , I Nw (it) I < A and if (u,v,w) G M then v £ Ny (it) and w E Nyy (u) ) is 
still NP -complete. 
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Proof. It is a direct consequence of the PCP theorem that there is a constant e > for which e — GAP- 3 SAT 
is NP-complete |Pap94[ . Applying the standard reduction from 3SAT to 3DM MGJ791 to GAP- 3 SAT imme- 
diately yields the desired result. To give an idea of parameter values, we obtain e ~ 1 — 1/8 and A = 6. □ 



3 Proof idea and zero-error case 

There is a generic classical MIP protocol for GAP-3DM: the verifier picks a random vertex u and sends it 
to each of the two provers, asking them to apply bijections it and a. In the case of a positive instance the 
provers send back ir(u) resp. a(u) and the verifier checks that (u, ir(u),a(u)) £ M. To enforce a bijection, 
the verifier performs another test with some probability: he picks random vertices u and v! and asks both 
provers to apply n. He checks that the answers are the same if u = v! and that the answers are different 
if u 7^ u'. To have a constant probability of detecting cheating provers, the verifier picks v! among the 
neighbors of the neighbors of u. Since the degree of the underlying graph is constant, the probability to 
detect a non-bijection is constant. For a negative instance only a small fraction of (u, vr(n), a(u)) are in M 
for any bijection, and hence the provers cannot cheat. 

The difficult part in giving a QMIP* protocol for GAP-3DM is to show that entanglement does not 
help the provers to coordinate their replies in order to cheat in a negative instance, i.e. to show reasonable 
soundness. The idea is to use quantum messages and quantum tests, like the SWAP-test, to enforce an 
(approximate) bijection from the provers. 

In this section we first describe a QMIP* protocol for 3-DM and show its correctness in the case of zero- 
error, i.e. under the assumption that the provers have to pass all the tests with probability 1. This allows us 
to present the basic ideas needed in Section 0] to relax the soundness to 1 — 2~°( n \ 

3.1 Description of the protocol 

The provers, called Alice and Bob, share some general entangled state |^), which might depend on the 
instance x of GAP-3DM. The verifier V, who has a workspace of O(logn) qubits, sends simultaneously 
one question to each prover, which consists of a single bit (it or a) and a register on log n qubits. We will 
use subscripts to indicate the registers sent to A and B and into which A and B will write their answers, 
i.e. \-)a is send to Alice, she performs some operation on her space and the register and sends it back, and 
similarly is sent to Bob. V begins by flipping two fair coins with outcomes ir/a, and sends the result of 
the first coin flip to the first prover, and the result of the second to the second prover. If both coins give the 
same result (it, it or a, a) the verifier does a set of tests that ensure that it resp. a are bijections (BIJECTION 
TEST-Test 1). Otherwise the verifier tests if the instance of GAP-3DM is positive (MATCHING TEST-Test 
2). Note that in a part of Test 1 we use the SWAP test [BCWW01 ], that measures how similar two quantum 
states | a) and \(5) are. Suppose \a) and \0) are given in two separate registers. An ancillary qubit is prepared 
in the state 4=(|0) + |1)). This qubit controls a SWAP between the two registers , and a Hadamard transform 
is applied to the ancillary qubit, which is then measured. The success probability, the probability to measure 



We denote elements of U by u and u', elements of V by v and v' and elements of W by w and w' . 

Test 1 (BIJECTION TEST) Let us assume that both coins gave tt (otherwise replace all 7r with a and 
v,v' € V by w, vJ G W). With probability 1/3 the verifier prepares one of the following states, sends the 
corresponding registers to A and B, receives their answers and performs a corresponding test: 
a) State: for a random u € U 



|0), is given by \ 



|(l + l(«l/3)| 2 )- 
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Test: This test incorporates three subtests: 

1) If the first register is in state |1) the verifier checks that the answers of the provers are the same. In 
other words he projects onto the space spanned by |0)|t>)A|v')_B i v ) v ' £ Kh accepts iff the 
result is positive and then controlled on the first register being |1) erases register 2 by XORing register 3 
onto register 2, such that register 2 is in the state \0)a- 

2) If the first register is in state |0), the verifier projects the second register onto Yl v \ v )a, accepts iff 
the result is positive and then erases this register by applying a unitary that maps J2 V \ v )a to |0)a- 

3) He measures the first register in the {|+), |— )} basis. If he gets |— ), he rejects, otherwise he accepts. 

b) Like a) but with the registers 2 and 3 swapped. 

c) State: 

- V] \u)\u) A \u')\u') B 

u,u' 

Test: Perform a SWAP-test between registers 1,2 and 3,4. Accept if and only if it succeeds. 

Test 2 (MATCHING TEST) If the coins gave different results, then for a random u G U prepare state 
\u}\u}a\u)b and send register 2 to Alice and 3 to Bob. Receive their answers. Measure all registers in the 
computational basis and get a triple (u, v, w) (or (u, w, v), depending on who got the it and who got the a) 
as a result. Accept if (u,v,w) G M and reject otherwise. 

Remarks: Note that the MATCHING TEST is completely classical. The first part of the BlJECTlON TEST, 
a)l) (and b)l)), simply checks that the provers give the same answer when confronted with the same ques- 
tion. This part of the test is in fact entirely classical. As will become clear, the second part, a)2), is included 
only for convenience as it allows us to introduce a handy basis the zero-error case. This test will be dropped 
in the general case. The third part, a)3) (resp. b)3)), serves to establish that the provers indeed implement 
a bijection in some basis, that might depend on u. However it is part c) of the BlJECTlON TEST, which 
is genuinely quantum, that allows us to show that there is a global basis in which the prover's action is a 
bijection. It is this test that links our results to the 5 in Conjecture [2] in the non-zero-error case. We do not 
know if it is possible to find a classical test that would establish this, but our attempts make us believe that 
it is unlikely and that we indeed need quantum messages to establish the result. 

3.2 Zero-error proof 

First note that the verifier requires only space and time 0(log n) for the execution of the protocol, if he has 
access to his input through an oracle that given u outputs all triples (u, v, w) G M, of which there are a 
constant number. Moreover perfect completeness (c = 1) follows trivially: for a positive instance of GAP- 
3DM there exist bijections ir : U — > V and a : U —> W (from Def. © such that if the provers apply the 
transformations \u) i— > |vr(n)) and \u) \a(u)} on their registers it is easy to check that they are accepted 
with probability 1 by the verifier. 

We now show the converse: if two provers are accepted by the verifier with probability 1 in the BlJEC- 
TlON TESTand with some constant probability in the MATCHING TEST, then the instance of GAP-3DM is 
positive. More precisely we show that if the provers pass the BlJECTlON TEST, then their actions corre- 
spond to bijections (this will be made precise below). Hence, if they also pass the MATCHING TEST then 
there must be an approximate matching. At the beginning of the protocol the joint state of A and B can be 
described as |*) = Yliel where {H) : z G 1} is some orfhonormal family (the Schmidt basis of A 

and B's joint state including their private workspace) and / can be arbitrarily large. Note that a priori there 
can be several valid bijections 7r, and <Tj such that (u, 7Tj(u), o~i(u)) G M for all u G U. In particular the 
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following is a perfectly valid action of A and B to pass the MATCHING Test: 



-^=y^ y \u)\u)A\u) B y^ y ai\i)\i) — ► -^y^ y ai\u)\iri(u)) A \ai(u))B(UA\i)) ® (V B \i)) 

V tl . T \/Tl 

v u i£l v u,i 

for some arbitrary unitary Ua on A's system and V B on B's. Here, A and B use their entanglement as a 
shared coin to chose one of the possible valid bijections. We will show that if they pass the BlJECTlON 
Test, this is the most general thing they can do (up to local unitaries on their systems before answering V's 
questions). We need some more notation to describe the action of Alice and Bob. Without loss of generality 
we assume that As and B's actions are unitary (by allowing them to add extra qubits to their workspace). 
Let A 71 " and A CT be the two unitaries that Alice applies to the question she receives and to her private qubits 
(including the entanglement) before returning her answer, depending on the first bit she receives. Similarly, 
Bob is described by B w and B CT . Write the action of A and B (we often omit the ir and a superscripts when 
the context is clear) as 

\u)\i) A n \u)\i) = £l«> «>*)> \u)\i) ■-► B w |u)|i) = YHv)\^{u,v,i)) 

V V 

We decompose A into sub-matrices A u,v corresponding to {\u}} and {\v}} in this definition. Similarly 
for B. A u,v is thus the matrix with column vectors {\ip{u,v,i)), i G /} expressed in some basis {|ej}}, 
independant of u, which we will define later, i.e. A^'J = (ei\ip(u, v,i)}. We would like to show that up to 
local unitaries on the second system we have A^u)^) = |7Tj(u))|z), i.e. \ip w (u, v, i)) = \i) if v = 7Tj(u) 
and zero otherwise. In what follows we will use the following fact, which can be easily computed from the 
definitions. Let D be the diagonal matrix having the ctj's on its diagonal. 

Fact 8. HEiei"; \f(u,v,i))\^(u',v',i))\\ 2 = \\A U > V D(B U '' V ') T \\ F where \\ ■ || 2 is the L 2 norm \\\v)\\ 2 2 = 
(v\v) and \\ ■ \\p is the Frobenius norm defined as ||^4||^ = Tr(^A). 

Lemma 9. Assume the provers pass the BlJECTlON TEST with probability 1. Then there exist diagonal 
projector matrices P u > v and Q u < v such that £ u P u > v = ]T v P u ' v = I and J2 U Q u > v = J2 V Q u ' v = I and 
unitary matrices U\ and V\ such that 

V(u,v)£UxV A u ' v = U 1 P U ' V U\ and B u ' v = VyQ u > v V±. 

The fact that all P u,v are diagonal projectors together with the conditions J2 U P u,v = Y^, v P u ' v = I 
ensures that for a fixed i and u there is exactly one v such that P u > v has a 1 in position i and vice-versa. This 
means that for fixed i, we can define a bijection 7Tj by letting 7Tj(u) be the unique v such that (P u ' v )i^ = 1. 
In other words if P = U\XU\, then P|n)|i) = Y^ v \ v )P u ' v \^i) = l^^))!^). U\ is a local unitary on the 
prover's register only. 

Proof. We begin with a claim summarizing the consequences of each of parts a), b) and c) of the BlJECTlON 
Test. 

Claim 10. As a consequence of Test 1, the following matrix relations hold for all u,u' £ U and v,v' £ V 

A u > v ' D(B U > V ) T = ifv' + v (la) 

A u,v D = A u,v D ( B u,vjT = D ( B u,v^T (lb) 

A U ' V D(B U '' V ') T - A U '' V 'D(B U ' V ) T = (lc) 
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Proof. Let us first analyze part 1. of Test la). If the first qubit is in the state 1 1) , the state of the system after 
the provers have sent back their answers is 

E \ V )a\ v ')b E ^I^O; v i v ',i)) 
v,v' i 

The probability to reject is given by the norm squared of the part of the state with v / v' , averaged over all 
u, and hence we get 

\ E iiE a <i^ tt ' u ' i )>i*(«,« , ,o>iil = ^ E \\A u ' v D(B u yff F = o (2) 

which proves Eq. ([Tab . 

For part 2. of Test a), if the first qubit is in the state |0), the state of the system after the provers have 
sent their answer is 

~/= E \ V "> A E \ V ) B E ai E \P( U '> *)) l*( n ' u ' »)) 

v v' V I u 

If provers pass part 2 of Test a) with probability 1, the state must be a tensor product with -7= J2 V ' W)a in the 
first register and hence the other registers must be independent of v' . In other words |ej) := Yl u ' W( u> i v ' ■> 0) 
is independent of v' . Note that since Alice's transformation is unitary, it must be that the set of vectors 
{ Ylv' \ v ')Yl\ l P{' u ' i v> 0)i * ^ ^1 are orthonormal, and hence the vectors \a) also form an orthonormal 

u 1 

basis. It is in this basis that we express the matrices A u,v . Note that in particular J2 U A u,v = I- From part 
2. of Test b) we similarly get a basis 

In part 3. of Test a) the probability to measure | — ) is given by the norm squared of the state 

5Zl«)£«i(£«' W(u',v\i))\V{u,v,i)) - \<p(u,v,i))\V(u,v,i))) 

V * 

averaged over all u. So we have for all u, v 

\\E<Xi(h) - Wu,v,i))) |*(W)>||1 = - A^)D{B^) T f F = 0, (3) 

i 

i.e. D(B U ' V ) T = A U ' V D(B U ' V ) T . From part 3. of Test b), similarly A U > V D = A u > v D(B U ' V ) T , which 
combined give Eq. (flbl) . 

We finally exploit Test 1(c). The SWAP-test succeeds with probability 1 if the norm of the state 

- Yj \u)\v)A\u')\v , ) B J2 a d\v( u ' v ' i ))\ Sif ( u '> v '> i )) ~ \v(.u',v',i)}\y(u,v,i)}) 
u,u',v,v' i 

is zero. This immediately implies Eq. (ITcb . □ 
Claim 11. The matrices A u,v are projectors. More precisely, 

Vu,veU xV A u ' v = (A U ^A U ' V (4) 
Proof. With the notation that (X)j is the jth column of a matrix X, write 

\v) ® (A u,v D)j = \v) <8 (A u > v D(B u > v ) T ) j = ® (A u > v ' ' D(B u > v ) T )j 

v' 

= Y,*iB^Y,\v')®Wu,v',i)) (5) 

i v' 
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where we used Q. Since <S> \<p(u, v' , i)), i G /} are orthonormal, we get aj((p(u, v, i)\ip(u, v, j)) — 

v' 

ajSjf = 0, i.e. (A u ' v y A u ' v D = D(B U > V ) T , which, using CUi, Anally gives Eq. ©. So A u < v is a 
diagonalizable matrix with eigenvalues in {0, 1}. □ 

Combining Eqs. £[b]> and £lc]> we have that A U ' V A U '' V ' - A U '' V 'A U ' V = for all u, u', v, v', i.e. the ma- 
trices A u ' v are mutually commuting, and thus simultaneously diagonalizable. Let U± be the diagonalization 
matrix. We have 

Vu,v£UxV A u ' v = U!P u ' v ul and B u ' v = V L Q u,1 V 1 t 
where P and Q are diagonal matrices with eigenvalues 0, 1. Finally, since the family {^|t;)(S>|v2(«, v, i)), i E 
/} is orthonormal, we have v, i)\ip(u, v,j)} = 5ij and hence ^2(A u ' v y A u ' v = Y2A U,V = I. 

V V V 

□ 

Lemma 12. For a negative instance of 7/-GAP-3DM /ff/je provers pass the BlJECTlON TEST with proba- 
bility 1 they will fail the MATCHING TEST with probability at least 1—7]. 

Without loss of generality assume the verifier sends ir to Alice and a to Bob. From Lemma [9] we 
know that Alice implements A 71 = U\VU\ and Bob W = VxQ^vl where P n \u)\i) = |?r«(u»|ei> and 
Q a \u)\i) = \<ji(u))\fi). Hence the state the verifier receives is 

\a(u)) := |u)A» A B» B = aMu)) b (UxDvA Ui\e,) Fi|/ fc ) (6) 

j,k v 7 h k 

t 2 

V measures the triple (u, iTj(u), crfc(n)) with probability (UiDV\) - k which is independent of u. For 
a negative instance we know that for any bijection ttj and for a fraction of at least 1 — rj of the u, 
[u, Ttj(u), (Tfc(n)) ^ M and so the provers fail Test 2 with probability at least 1 — rj. 

Note that the proof still works if the state that the verifier receives is not exactly equal to the state in ©. 

Claim 13. Assume the state \a'(u)) of the verifier after receiving the provers registers in the MATCHING 
Test is such that ^ \(a(u)\a'(u))\ 2 < 5, then in the case of a negative instance o/ry-GAP-SDM they 
will fail the MATCHING TEST with probability at least 1 — rj — 5. 

This follows because the two density matrices p = -Y^ u \u)(u\ l S)\a(u)}(a(u)\ and/)' = - ^2 u \u)(u\® 
\a' (u)} (a' (u)\ have fidelity 1 — 5 and hence the probability to accept when given p differs from the proba- 
bility to accept when given p' by at most 5. 



4 Decreasing soundness 

In this section we prove Theorem Q] and Corollary [3] To deal with error, we begin by slightly modifying the 
protocol introduced in 13- 1 [ We only make changes to parts a) and b) of the BlJECTlON TEST. 

Part 1. of test a) (and b)) is modified in the following way: after receiving the prover's answers, we 
will flip a fair coin and, if the result is 0, then we will project onto the space spanned by the vectors 
{|l)|?;)|i>), |0)|t/)|i;) ,v' S V,v £ N\/{u)} and accept if and only if we get a positive result. If the re- 
sult of the coin flip was zero, we project onto {|l)|t>)|t>), |0)|i/)|t>) ,v,v' S V} as in the original test, and 
proceed directly to part 3 of the test. We thus completely drop part 2 of Test a (and b), which was used in 
the zero-error case to introduce the basis |ej). Since we do not want to deal with approximately orthonormal 
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bases, we will replace it by a perfectly orthonormal basis |e$), with the caveat that it is inside a larger Hilbert 
space. All the other tests remain the same. 

As in the zero-error proof, the key lemma states that provers who pass the BlJECTlON TEST with prob- 
ability 1-e must apply approximate bijections. More precisely, we prove the following 

Lemma 14. Assume the provers pass the BlJECTlON TEST with probability 1 — e. Then there exist a 
constant C > and diagonal projectors P u > v and Q u ' v such that Y^, u P u ' v = Ylv P U ' V = ^ an d Ylu Q U ' V = 
Ylv Q U ' V = I an d unitary matrices U\ and V± such that 

- ^2 \\( AU,V - UxP^U^Dfp < C n e and - II " VxQ u > v vl)D\\ F < C n e. 

To conclude Theorem [TJ from this lemma, note that, as in Section [3721 the verifier uses space O(logn). 
Perfect completeness follows again trivially. Let e be the constant from Fact|7J Suppose that the two provers 
pass the BlJECTlON TEST with probability 1 - C~ n e/2, and the MATCHING TEST with constant probability 
1 — e/2. Then, Lemma [141 together with Claim [T3l imply that the instance of GAP-3DM must be positive. 
This proves that our protocol has soundness 1 — C~ n . To conclude Corollary observe that the bottleneck 
to decreased soundness comes from Test lc) and Lemma l20l From the proof of Lemma [14] it follows that 
if Conjecture |2] is true for some 5(m, e), then Lemma [T4l is true when C n e is replaced by 5(C'n, C"e) for 
some constants C , C" > 0. 

We will use the following easy facts in our proof: 

Fact 15. (a) Let \\ ■ \\ op be the operator norm (largest singular value). If \\A\\ op < 1 then \\AB\\ F < 
\\B\\f- (b) (Triangle inequality) For a constant number of matrices X%, . . . , X/± we have \\ X^iLi ^11% — 

(Et 1 ||^l|F) 2 <A 2 maXi (||jr i |||-) 

Fact 16. Let U = ( - 1 ) be a unitary matrix such that \\U2D\\% = 0{e) and Uq is a square matrix. 
Then there exists a unitary matrix Uq such that \\(Uq — Uo)D\\^ = 0(e). 

Proof. Since WU = I we have that \\(U^ U - I)D\\ 2 F = 0(e). Let U = PZQ^ be the singular value 
decomposition of Uq with singular values \ > and define Uq = PQ^ (which as a product of unitaries 
is unitary). Then U*U Q = Q&ZQ\ and we get \{pZ - I)<$Df F = Eij I (A? - l)Qj,i a jf = 
Since |Aj — 1| < |Aj — l|(Aj + 1) = |A? — 1|, we finally have 

\\(U Q - U )Df F = \\(Z- I)Q ] )Df F = |(Ai - VQtiOjl 2 < K A f " l )Qi,W\ 2 = °( e )- 

□ 



Notations: Let us start by describing the matrix notations we use in the proof of LemmafT4l As in Section 
rjj j^u,v j s S q Uare ma trix with columns {\<p(u,v,i)), i £ J) expressed in a basis \e%) which will be 
defined later. Let := Ylv' W) Ylu' W( u ' > v '^))- The family {|§j), i G /} is orthonormal as an 
immediate consequence of the prover's unitarity. This family is included in the Hilbert space H spanned by 
all vectors of the form \v)\i) for v G V and i G I. We complete this family to a basis {|ej), i G J} of H, 
where \ J\ = \I\ ■ \V\. Letting \(p(u,v,i)) = ^2 V , \v')\ip(u,v,i)), A u,v is the rectangular matrix with 

column vectors \(p{u, v, i)) expressed in the basis |ej). Define A' u ' v as the matrix equal to A u,v with all rows 
below the |/|th row set to 0. Finally Ia is the mattix of same dimensions as A formed by an |/| x |/| block 
equal to the identity matrix over a rectangular block of zeroes, and A u ' v = I^A U ' V is the upper block of A. 
Matrices B u > v , B u ' v , B> ' , B u ' v and I B are defined in the same way for the vectors \^(u, v, i)), in bases 
\fi) and \f). The relations between all these matrices will be given in ( flOl ) and ( [TBI . 
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Proof of Lemma\T^s The idea is to follow the lines of the proof of Lemma [9] and to prove approximate 
versions of Claim [Kj] (Claim [17J and Claim[II](Claim[l8]>. 

Claim 17. The following matrix relations hold as a consequence of Test 1 



-E( E \\A U ' V 'D(B U ' V ) T \\ 2 F + \\A U ' V ' D{B u > v ) T \\l\ = 0(e) (7a) 

u v£N v (u) v<£N v (u);v' ' 

-^T \\A U > V Dll - A u ' v D(B u ' v ) T f F = 0(e) - V \\A u ' v dE - I A D(B u ' v ) T \\l = 0(e) (7b) 



n ' — ' n 

u,v u;v&N v (u) 



n 2 



J2 \\(A U ' V D(B U '' V ') T - A U '' V 'D(B U ' V ) T \\ 2 F = 0(e) (7c) 

u,u' ;v£Ny (u);v' eiVy («') 



Proof. Since we assume that the provers pass Test 1 with probability at least 1 — e, they must pass each of 
the Tests la, lb and lc with probability at least 1 — 3e. 

We first study the consequences of Test la. The verifier flips a fair coin. The provers must have a success 
probability of at least 1 — 6e in any of the two cases. If the verifier got a 0, Eq. (0) becomes 

iW ]T \\A U > V 'D(B U > V ) T \\ 2 F+ E \\A u > v 'D(B u > v ) T \\i) < 6e 

u ^v£N v (u) v<£N v (u);v' ' 

v':v'y^v 

which gives dTal) . If the verifier's coin flip resulted in a 1, assuming the provers pass the projection test in 
part 1, with the convention that |0)a = ^= J2 V ' W)a, the state is projected onto 

■^=^2\v') A \v) B (jVo|0> J^ai ^ |¥>(«'y, i))|*(t*,t;, *)) +N 1 \l)J2uMu,v,i))\y(u,v,i))\ 



n 
v.v 



where Nq and N\ are normalization factors, N$,N\ > 1/^1 — 6e. In the following we will not write these 
renormalisation factors with the understanding that the corresponding norms change by at most factors of 
1 ± 6e < 2, and we will write 0(e) for c • e where c > is some constant independent of n. In part 3, the 
probability of measuring |— ) is given by the (averaged over u) norm square of 



Ei^E^-iE^'ME 

v i v 1 \ u' 



\ip(u',v',i))\^(u,v,i)) - \(p(u,v,i))\V(u,v,i)) 



The norm inequality above can be rewritten in terms of the matrices A u,v similarly to Eq. Q 

- E ii E (i e ~*> - 1^< w ' o» «> o>iil = I E ii - A u nD(B u n T \\l = 0® 



n £ — ' 1 — ' n 

u:v % 



giving the first part of Eq. d7bl . We obtain a symmetrical relation for matrices B from Test 2b). We combine 
them, using the triangle inequality and summing over v 6 Ny(u) only, to obtain the second part of Eq. d7bl . 
Finally, (fTcT ) follows directly from succeeding Test lc) with probability at least 1 — 3e. 

□ 

Claim 18. The matrices A u ' v are almost projector matrices. More precisely, 

I ^ \\(A U ' V -(A u ' v )^A u ' v )D\\ 2 F = 0(e). (8) 
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Proof. Note that the matrix ADI^ has zero columns starting with the |7| + 1st column and the matrix 
IaDB t has zero rows starting with the |7| + 1st row. Then the first part of (1751 ) implies that 

- \\(A U ' V - A' u ' v )Df F = 0{e) (9) 

u;v&N(u) 

and similarly for B' . 

Let \i) = A= J2 V \ v )\i') e ^7- Complete to a basis {\i}, i G J} of 77. Let {7 be the unitary that maps |e^) 

to Then t7^4 is a rectangular matrix consisting of a block equal to the original A matrix over a block of 
zeroes. This can be restated as UA = IaA. Relation (© can then be rewritten as 



- V \\(I A A u > v -UA> u ' v )D\\ 2 F = 0(e) 

n. ^— ' 



n 

u;v£N(u) 



(10) 



We now proceed similarly to the proof of ©. We have (A u ' v> D(B u > v ) T )j = £\ Oi-BVf |£(u, v',i)) and 



E a 4T E I 77 ') ® i# u > ^ *')> = i«> ® (i u '^(s^) T ) . + ^ ® (a«'*'d(s«'«) t ) . 

Since the l v ) <8> v, i)), i G 7} are orthonormal, summing over u, i, j and averaging over u, using 
(TTab . (1751 ) and (<p(u, v,i)\<p(u,v, j)) = ((p(u,v,i)\ip(u,v,j)), this implies 



- E E \ a ^ti ~ aj{ip{u,v,i)\Lp(u,v,j))\ 2 = 0(e) 

so that i E U ;« 6 iV v ( u ) ||£>(£"^) T - (A u ' ,, )tA u ' ,; 7J)||| = 0(e), which using d7bj implies that 

I - (A u ' v ) t ^l u,,, )7J||| = O(e). (11) 

«;«6ivy(u) 

Let S'"' 1 ' = ( J 4"'' i; )t^4 M . t ' be the square matrix with coefficients = (ip(u,v,i)\ip(u, v, j)}. We now 
show that i E« || (7 — Evejv^u) S U ' V )D\\ F = O(e). Considering first only the contribution of the diagonal 
entries, we get 




u,v,i))\\ 2 



P) ^E^l 1 " E \\Mu,v,i))\\A=0(s). (12) 

J j u,i \ v£N v (u) J 



2 



For the first inequality we use \\ip(u,v,i)\\ 2 = 1, so that < 1 — YlveN v (u) llv 3 ^ v i *)l| 2 — 1- Now 
combine © with O to get ± E U ;«^jv v («) P" ,, ' /:) ( / b) T |I| = - which implies that 
7iY, U ;vtN v {u),i a 'i\\\^ u i v i i ))\\ 2 = 0(e) (since \\\ip(u,v,i))\\ = \\\<p(u,v,i))\\). As^2 Vji al\\\<p(u,v,i 
1 = J2i a i' we § et tne second inequality in (fT2l) . 

As E^ I u )l9 :;> (' u ) v > *)) i s an orthonormal family over i, we have that for all u, E« S u,v = 7. All S'"' 1 ' 
being positive matrices, 7 — J2 v eN v (u) $ u,v is also positive, write it as Y*Y. Then the diagonal coefficients 
of 7 — J2 v eN v (u) S u ' v w& me norms of the column vectors of Y, so [|Y\D[||, = 0(e). Moreover, since 
Y^Y < I, Y has operator norm less than 1. This implies that ||y^y7J>|||, = 0(e), yielding the desired 
inequality. 
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Summing over v and using Fact [T51 together with Q, (fTTT >. we get 

^EiK E in,,; - E ^^) J Diil = o(A- e ) = o( £ ) 



n 

« v£N v (u) v£N v (u) 



so, by (23, since C/i = I A A, we get that \ J2 U \\(I A J2 ve N v (u) A "' V ~ UIa)D\\ 2 f = 0(e). Let U be the 
upper left block of U and U2 its lower left block. From the definition of I a, this implies that HL^^H 2 ? = 
0(e) and ± £ u IK^o " E ve N v (u) A U > V )D\\ 2 F = 0(e). From Fact[Hwe get a unitary C/ such that \\(U - 
U )D\\ F = 0(e) and hence \\(Uq - J2veN v (u) A U ' V )D\\ F = 0(e). We now choose the basis | e^) in which 
matrices A u ' v are expressed to be the basis defined by Uq as \e{) = Uq\i). Equation (fTOl) becomes 

- ^ ||(i u ' v -^)D||| = 0(£) (13) 

u;v£Ny(u) 

which, together with ©, provides the link between matrices A, A and A. We also have that i ^ u || (J — 
SveiVy(«) ^"'^-^Hf = 0(e), and, combining (TTTb and (PT31 proves the claim. □ 

Claim 19. There exist projectors P u ' v such that 

I \\(A U ' V -P u ' v )D\\ 2 F = 0(e) (14a) 

E ||(jwp«V _ p«Vp«.»)Z)|||, = o(e) (14b) 

u,u';tieAr v (u);i/eiVV("') 

Proof. Claim[T8]implies that on average A^yl (and hence A) has eigenvalues close to or 1. More precisely, 
combining G0 and © with the triangle inequality, ± Y. u ,veN v (u) \\D(B U ' V ) T - (A u ' v )^ A U > V D\\ 2 F = 0(e). 
So i E u ,^eiv v (n) IIS^D^"'^ - (S U '") 2 I>|||. = 0(e), since S has operator norm less then 1. Using 
(P7bl to replace ST>P T by ST>, we finally get 

1 y- ||(5"," _ (S U > V ) 2 )D\\ 2 F = 0(e) (15) 



I? 2 



n 

u,i;£JVv(u ) 



Diagonalize 5"^ as S = U u,v Z U,V (U U,V )^ , where Z is diagonal and let A"'" be its eigenvalues. Then (fT3T > 
is rewritten as 

l - E Ei( A r-(Ar) 2 )^i 2 =o( £ ) 



n 

u,i;eiVy(u) ij 

The Aj are such that < \ < 1. Let /Xj be the nearest integer to A,. It is easy to check that |Aj — < 

2Ai(l-Ai),so 

\ E Ei( A r-Mn^f«/<4 E EK A r-(Ar) 2 )^r«ii 2 =o(-) 

Let P'"'" be the diagonal matrix with entries [/% ,v if v S Ny(u), and p'"- 11 = if v ^ iVy-(ii). Let 

pu,v ._ jju,v p/u,v (jju,v^] r p]- len 

- E I' { SU ' V - U U ' V P' U ' V (U U ' V )A D\\ 2 F = 0(e). 

u;v£Ny (u) 

By Claim [HJ this implies Eq. (fl4"al ). 

From (|7cT >. using successively (I14al ). (TTbl and again (I Hal ) together with the triangle inequality, since the 
projectors P have operator norm bounded by 1, we get Eq. (1 1 4b I t . □ 
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By Markov's inequality Eq. (1 14bb implies that for a subset U' C U of size (1 — 0(e))|C/| we have 
that || (p«^p«>' _ P U '.«' J P".«)D||2 = 0(e) for u,u' G [/'. This allows us to apply the following lemma, 
proving Conjecture |2]for 5 = 2°^e. 

Lemma 20. Assume that projectors P\ , . . . , P m are such that Vi , j we have IKPiPj-PjP^DWf < e. Then 
there exist diagonal projectors Qi, . . . , Q m , and a unitary matrix U, such thatMi \\ (Pi — UQiU^)D\\ 2 F < c n e 
for some constant c. 

Proof. The proof is by brute force successive diagonalization. Choose a basis in which Pi is diagonal and 
has first a block of Is on the diagonal, followed by Os; this defines four blocks. Because of the commutation 
relations we have that in this basis for all other p the sum of the norms squared of the upper right and lower 
left blocks is bounded by e. Set these blocks to in each P,, apply a unitary that diagonalizes the upper 
left and lower right blocks, round the eigenvalues to the closest integer (0 or 1), and apply the inverse of 
this unitary. After this first round we are left with new projectors P\ , . . . , P^ which are block-diagonal in 
a common block structure, with the two off-diagonal blocks being 0. Moreover, because of the cutting and 
rounding, the norms of the commutators of the new matrices will be bounded by ce for some constant c. 
They all commute exactly with Pi . Pi will not be changed any more. 

In the next round choose a (block-diagonal) basis in which P 2 X is diagonal such that inside the two blocks 
defined by Pi we first have a run of Is on the diagonal, followed by 0s. Note that Pi stays diagonal in this 
basis, since it was either the identity or zero on each of the two blocks we are now modifying. For the 
remaining projectors (P3 1 , P4, . . .) set the four resulting off-diagonal sub-blocks, which have norm at most 
ce, to and re-round the eigenvalues as before. The resulting projectors commute with Pi and P\ and 
the norm of their pairwise commutators is now bounded by c 2 e. Proceed in this way one by one with the 
remaining projectors. Each time the norms of the commutators are at most multiplied by c. This gives the 
desired result. □ 

Applying Lemma l20l to the P' U ' V J we get a set of commuting projectors Q u,v that are simultaneously 
diagonalizable, and close to the p' u ' v in Frobenius norm. To complete the proof of Lemma [141 it remains 
to prove that we can slightly modify these projectors so that they sum to the identity on both u and v. 
Recall that we proved that A £ u ||(E« 6 JV v (u) ^ ~ / )- D Hf = °( e )- From Claims HE] and ED, we get 
£ E« \\(Ev&n v (u) Q U,V ~ ^Dfp = 0(e). We can therefore slightly modify each Q into matrices Q' 
that sum exactly to the identity on v (recall that P u,v = whenever v ^ Ny(u)). Now consider the first 
prover's unitary A. Change the basis of A using the projector's simultaneous diagonalization unitary U. Let 
A' be the matrix with blocs Q' u ' v . Fix v and consider the set of lines of A corresponding to this v. Since A 
is unitary, each of these lines has norm 1. Moreover by (fT4l they are close to the corresponding lines of A', 
which have coefficients in {0, 1}. Therefore these lines can be slightly modified to have exactly one 1 per 
line, yielding matrices Q" u,v that sum to the identity on u, and are still close to the original Q u,v . 

□ 

5 Conclusion and future work 

We have attempted to devise a test (our BlJECTlON Test) which forces the provers to implement a bijection 
on the message register. Obviously the bottleneck to decreasing further the soundness of our protocol 
is the increase in error when we go from almost commuting matrices to almost diagonal matrices. The 
question of how well almost commuting matrices can be approximated by diagonal matrices has been studied 
extensively in the theory of operator algebras, albeit mostly when the norm in question is the operator norm, 
and not the Frobenius norm. One might be tempted to conjecture that sets of almost commuting self-adjoint 
matrices can be perturbed slightly to a commuting set (that they "nearly" commute). In fact for the case 
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of just two matrices, this was a famous conjecture by Halmos IIHal761 (Are almost commuting Hermitian 
matrices nearly commuting?). It is known that this conjecture is wrong for two unitary matrices: Voiculescu 
[Voi83|] gave an example of two unitary n-dimensional matrices A and B such that \\AB — BA\\ op < 1/n 
but for all commuting A 1 , B' we have [| A — A' || ^ + 1| B — B' 1 1 OJ3 > 1 — 1/n. The proof of the latter inequality 
depends on the second cohomology of the two-torus. Halmos' conjecture was disproved in the case of three 
self-adjoint matrices. Finally Halmos' conjecture was proved by Lin [Lin97 ] by a "long tortuous argument" 
HDSOll using von Neuman algebras, almost 20 years after the conjecture had been publicised. 

In the case of projectors the Halmos' conjecture is easy to prove, both in the operator and in the Frobenius 
norm. This is due to the fact that any two projectors have a common basis in which they are block-diagonal 
with at most 2-by-2 blocks. It is tempting to conjecture that Lemma [20] holds with constant increase in the 
error. We give here an example, due to Oded Regev, that gives evidence that Conjecture [2]might be false for 
5 = 0{^m)e. 

Candidate counterexample: Let D be always a multiple of / such that \\D\\p = 1 (D's dimensions will 
adapt to the dimensions of the matrix it is beeing multiplied by) and 

'-(i!) *-(!-.) s\) 

where r/ = y/ (2 — e)e, such that W has eigenvalues 1 and —1. As eigenvalues multiply when matrices 
are tensored, we have that any tensor product of n of these matrices (of dimension N = 2 n ) has exactly 
half eigenvalues 1 and half —1. To any such tensor product we will add I® n and divide by 2 to make it a 
projector of rank 2"~ 1 = N/2. Note that the commutator of two such projectors equals the commutator of 
the two tensor products. We omit the ® and write e.g. IIIZW for I <g) / <g) I (g) Z (g) W. We call the first 
tensor factor position 1, the second position 2 and so on, so IIIZW has a Z in position 4. The weight of 
such a tensor product is the number of positions different from /; so the weight of IIIZW is 2. 

We construct a set of m such tensor products of weight yjm with the property that any two of them 
intersect only in at most one position, where intersect in position i means that both matrices have a tensor 
factor different from / in position i. Note that the norm of the commutator of any two tensor products that 
intersect in one position is equal to the norm of the commutator of the matrices in this position. For example 
\\[IWZZ,IWIW]D\\ F = \\(IWZ®[Z,W])D\\ F = \\[Z,W]D\\ F . We have ||[Z,W]D|||. < 8e. 

Choose m such that y/m is a prime. Let us arrange the m positions in a square of length %/m. Each 
projector has I everywhere except on a line (modulo \fm), where its weight is concentrated. Note that every 
two lines intersect in at most 1 position and that there are at least m such lines (y/m for each of the y/rn 
"angles"). For the positions on the line let us randomly pick Z and W with probability 1/2 each. 

We would like to show that there is a good basis, i.e. a basis in which all the projectors are roughly 
diagonal. Given a projector P with, say, a Z in position i, there are several other projectors that intersect 
with P in % and about half of them will have a W in position i. So the good basis that we are looking for 
must lie somewhere "between" Z and W. But since this is true for all the positions where P is different 
from /, there are about y/m/2 matrices that are misaligned with P. No matter what basis we finally chose, 
as long as it is a tensor-product basis, 0(y/m) of the positions will have something of the form ±(1 — e/2) 
(roughly) on the diagonal. This means that the weight on the diagonal is roughly (1 — e/2)^ 1 — yjme 
and hence the off-diagonal weight is 0{y/me) and hence 5 = Vl{-\/me). This is true when the good basis 
has a tensor structure, at least, but our search for other good bases has not been successful. 

Two avenues remain: it might be that the projectors that arise in our proof system have a special structure 
which allows to prove approximate diagonalization without too much increase in error. Or else it could be 
that Conjecture [2] is true for some S = poly(n)e, or even constant 5. In the latter case this would mean that 
there is some good non-tensored basis for our counterexample. 
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We have proved our results for a "scaled down" version, where the verifier has logarithmic workspace 
and the quantum messages exchanged have a logarithmic number of qubits. It is possible to scale up these 
results: by carefully choosing a NEXP-complete version of GAP-3DM, with \U\ = \V\ = \W\ = 2 n and 
\M\ = 0(2 n ), such that the degree remains constant, our proof works with messages of length 0(n) and a 
polynomially bounded verifier to imply NEXP C QMIP* X s (2, 1) with soundness s doubly exponential in 
n. Note that in this case the verifier cannot read his input in polynomial time. However, given u G U he 
only needs to be able to find all (constantly many) (v, w) G V x W such that (u, v, w) G M. The details of 
this construction will be given in an ulterior version of this paper. 

We hope that our proof technique will be useful in other contexts. For instance one could imagine 
using it to give quantum interactive protocols for other problems, both NP-complete or not. Preliminary 
attempts have shown that similar techniques work to give QMIP* -protocols for 3COLORING. Or one 
could try to give quantum interactive protocols for problems that are between P and NP-complete, and base 
QMIP* £ EXP on the hardness of those. 
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